STIGQter STIGQter: STIG Summary: Application Layer Gateway Security Requirements Guide Version: 2 Release: 4 Benchmark Date: 01 Jul 2026:

The ALG that is part of a CDS, when transferring information between different security domains, must apply the same security policy filtering to metadata as it applies to data payloads.

DISA Rule

SV-204991r1137557_rule

Vulnerability Number

V-204991

Group Title

SRG-NET-000328

Rule Version

SRG-NET-000328-ALG-000078

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If the ALG is part of a CDS, configure the ALG to apply the same security policy filtering to metadata as it applies to data payloads when transferring information between different security domains.

Check Contents

If the ALG is not part of a CDS, this is not applicable.

Verify the ALG is configured to apply the same security policy filtering to metadata as it applies to data payloads when transferring information between different security domains.

If the ALG is not configured to apply the same security policy filtering to metadata as it applies to data payloads when transferring information between different security domains, this is a finding.

Vulnerability Number

V-204991

Documentable

False

Rule Version

SRG-NET-000328-ALG-000078

Severity Override Guidance

If the ALG is not part of a CDS, this is not applicable.

Verify the ALG is configured to apply the same security policy filtering to metadata as it applies to data payloads when transferring information between different security domains.

If the ALG is not configured to apply the same security policy filtering to metadata as it applies to data payloads when transferring information between different security domains, this is a finding.

Check Content Reference

M

Target Key

2904